Architecture |
IMAGE_FILE_MACHINE_I386
|
---|---|
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
Compilation Date | 2006-Sep-21 13:33:38 |
Info | Matching compiler(s): | MASM/TASM - sig2(h) |
Suspicious | PEiD Signature: |
dUP 2.x Patcher --> www.diablo2oo2.cjb.net
dUP 2.x Patcher -> www.diablo2oo2.cjb.net |
Suspicious | Strings found in the binary may indicate undesirable behavior: |
Contains references to system / monitoring tools:
|
Suspicious | The PE is possibly packed. | Section .text is both writable and executable. |
Info | The PE contains common functions which appear in legitimate applications. |
[!] The program may be hiding some of its imports:
|
Malicious | VirusTotal score: 36/69 (Scanned on 2021-07-27 00:06:13) |
MicroWorld-eScan:
Trojan.Generic.19635503
FireEye: Generic.mg.9019e33f6c223b99 CAT-QuickHeal: HackTool.Patcher.A ALYac: Trojan.Generic.19635503 Cylance: Unsafe Sangfor: Trojan.Win32.Heuristic.rg K7AntiVirus: Riskware ( 0040eff71 ) Alibaba: HackTool:Win32/Patcher.e5fb4f9a K7GW: Riskware ( 0040eff71 ) Cybereason: malicious.f6c223 Arcabit: Trojan.Generic.D12B9D2F Symantec: Trojan.Gen.2 ESET-NOD32: Win32/HackTool.Patcher.A potentially unsafe APEX: Malicious Paloalto: generic.ml BitDefender: Trojan.Generic.19635503 SUPERAntiSpyware: Hack.Tool/Gen-Patcher Rising: Trojan.Generic@ML.100 (RDML:Ep2VCOTuBiX3JdthpIjqHw) Ad-Aware: Trojan.Generic.19635503 Sophos: MassDown (PUA) Comodo: TrojWare.Win32.Patcher.~B@fptr VIPRE: HackTool.Win32.Keygen McAfee-GW-Edition: BehavesLike.Win32.BadFile.qt Emsisoft: Trojan.Generic.19635503 (B) SentinelOne: Static AI - Malicious PE Webroot: W32.Hacktool.Gen MAX: malware (ai score=85) Microsoft: HackTool:Win32/Keygen GData: Win32.Trojan.PSE.N7LEZ1 Cynet: Malicious (score: 100) McAfee: Artemis!9019E33F6C22 Malwarebytes: HackTool.FilePatcher Yandex: Trojan.GenAsa!fOK2YxVS0uM Ikarus: Generic.Win32.Virtools-Hacktools Fortinet: Riskware/Patcher BitDefenderTheta: Gen:NN.ZexaF.34050.dqW@a0VTFhl |
e_magic | MZ |
---|---|
e_cblp | 0x90 |
e_cp | 0x3 |
e_crlc | 0 |
e_cparhdr | 0x4 |
e_minalloc | 0 |
e_maxalloc | 0xffff |
e_ss | 0 |
e_sp | 0xb8 |
e_csum | 0 |
e_ip | 0 |
e_cs | 0 |
e_ovno | 0 |
e_oemid | 0 |
e_oeminfo | 0 |
e_lfanew | 0xb8 |
Signature | PE |
---|---|
Machine |
IMAGE_FILE_MACHINE_I386
|
NumberofSections | 4 |
TimeDateStamp | 2006-Sep-21 13:33:38 |
PointerToSymbolTable | 0 |
NumberOfSymbols | 0 |
SizeOfOptionalHeader | 0xe0 |
Characteristics |
IMAGE_FILE_32BIT_MACHINE
IMAGE_FILE_EXECUTABLE_IMAGE
IMAGE_FILE_LINE_NUMS_STRIPPED
IMAGE_FILE_LOCAL_SYMS_STRIPPED
IMAGE_FILE_RELOCS_STRIPPED
|
Magic | PE32 |
---|---|
LinkerVersion | 5.0 |
SizeOfCode | 0x2200 |
SizeOfInitializedData | 0xb400 |
SizeOfUninitializedData | 0 |
AddressOfEntryPoint | 0x000021A0 (Section: .text) |
BaseOfCode | 0x1000 |
BaseOfData | 0x4000 |
ImageBase | 0x400000 |
SectionAlignment | 0x1000 |
FileAlignment | 0x200 |
OperatingSystemVersion | 4.0 |
ImageVersion | 0.0 |
SubsystemVersion | 4.0 |
Win32VersionValue | 0 |
SizeOfImage | 0x11000 |
SizeOfHeaders | 0x400 |
Checksum | 0 |
Subsystem |
IMAGE_SUBSYSTEM_WINDOWS_GUI
|
SizeofStackReserve | 0x100000 |
SizeofStackCommit | 0x1000 |
SizeofHeapReserve | 0x100000 |
SizeofHeapCommit | 0x1000 |
LoaderFlags | 0 |
NumberOfRvaAndSizes | 16 |
user32.dll |
SetWindowRgn
SetWindowLongA SetFocus SetWindowTextA ShowWindow SetDlgItemTextA SetClassLongA SetCapture SendMessageA ReleaseCapture RedrawWindow PtInRect OffsetRect MessageBoxA LoadIconA LoadCursorA IsDlgButtonChecked InvalidateRect GetWindowRect GetWindowLongA GetParent GetDlgItemTextA GetDlgItem GetDlgCtrlID GetCursorPos GetCapture GetActiveWindow EndDialog DrawTextA DialogBoxParamA CheckDlgButton CallWindowProcA |
---|---|
kernel32.dll |
RtlZeroMemory
CompareStringA GetModuleFileNameA SetCurrentDirectoryA CreateDirectoryA FlushFileBuffers WriteFile lstrlenA lstrcpyA lstrcmpiA lstrcatA WinExec CloseHandle CopyFileA CreateFileA CreateFileMappingA DeleteFileA ExitProcess ExpandEnvironmentStringsA FindResourceA FreeLibrary GetCommandLineA GetFileAttributesA GetFileSize GetModuleHandleA GetProcAddress GetSystemDirectoryA LoadLibraryA LoadResource MapViewOfFile RtlMoveMemory SetEndOfFile SetEnvironmentVariableA SetFileAttributesA SetFilePointer SizeofResource UnmapViewOfFile |
shell32.dll |
ShellExecuteA
|
gdi32.dll |
GetStockObject
RoundRect SelectObject CreateFontIndirectA CreateSolidBrush ExtCreateRegion GetObjectA SetTextColor SetBkMode SetBkColor |
comctl32.dll |
InitCommonControls
|
advapi32.dll |
RegCreateKeyExA
RegQueryValueExA RegOpenKeyA RegCloseKey |
comdlg32.dll |
GetOpenFileNameA
|
XOR Key | 0xaf012b6f |
---|---|
Unmarked objects | 0 |
19 (8078) | 101 |
18 (8444) | 9 |
Resource objects (VS98 SP6 cvtres build 1736) | 1 |